Insider Threat Prediction Using Graph Analysis

Authors

DOI:

https://doi.org/10.54536/ajdsai.v2i2.8088

Keywords:

Cybersecurity, Detection Method, Graph Analysis, Insider Threat, Organizations

Abstract

The insider threat is still among the most difficult cybersecurity risks because of the access and capabilities of insiders to hide malicious or careless actions in the ordinary operations. The rules-based system, statistical anomaly detection and traditional machine learning tools are not always efficient in identifying the relational and contextual dependence in an enterprise setting which limits predictive capability as well as high false-positive. This paper presents a graph-baseds model of active preemptive insider threat detection. The Insider Threat Dataset of Multi-source behavioral logs of Classified Environments are converted to a heterogeneous interaction graph, where the nodes represent users, devices, and resources, and the edges indicate the frequency of interaction, sensitivity, and time patterns. Normative measures such as degree, between, eigenvector centrality, community membership, motif patterns and PageRank are derived to display aberrant relational activity. Empirical analysis has shown that a higher number of off-hours of printing/burning, larger volumes of data being exfiltrated, longer occupancy duration, and high-risk travel occur in malicious insiders occupying more influential network positions (much higher PageRank). The full prediction accuracy (FNNs classify every sample correctly) of Graph Neural Networks (GNNs) is high (F1 = 1.0, AUC = 1.0), which is significantly higher than that of the traditional baselines (Random Forest: F1 = 0.7576; XGBoost: F1 = 0.6753). The findings demonstrate the effectiveness of the graph-based methods in providing high-quality behavioral dependencies, with better accuracy and fewer false alarms and greater explainability in real-life insider risk monitoring.

References

Abiramasundari, S., & Ramaswamy, V. (2025). Distributed denial-of-service (DDOS) attack detection using supervised machine learning algorithms. Scientific Reports, 15(1), 13098. https://doi.org/10.1038/s41598-024-84879-y.

Agrafiotis, I., Nurse, J. R., Goldsmith, M., Creese, S., & Upton, D. (2018). A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate. Journal of Cybersecurity, 4(1), tyy006. https://doi.org/10.1093/cybsec/tyy006

Almazrouei, O. S. M. B. H., Magalingam, P., Hasan, M. K., & Shanmugam, M. (2023). A review on attack graph analysis for iot vulnerability assessment: challenges, open issues, and future directions. IEEE Access, 11, 44350-44376. https://doi.org/10.1109/ACCESS.2023.3272053

Alohaly, M., Balogun, O., & Takabi, D. (2022). Integrating cyber deception into attribute-based access control (ABAC) for insider threat detection. IEEE Access, 10, 108965-108978. https://doi.org/10.1109/ACCESS.2022.3213645.

Alzaabi, F. R., & Mehmood, A. (2024). A review of recent advances, challenges, and opportunities in malicious insider threat detection using machine learning methods. IEEE Access, 12, 30907-30927. https://doi.org/10.1109/ACCESS.2024.3369906.

Aslan, Ö., Aktuğ, S. S., Ozkan-Okay, M., Yilmaz, A. A., & Akin, E. (2023). A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions. Electronics, 12(6), 1333. https://doi.org/10.3390/electronics12061333.

Bajao, N. A., & Sarucam, J. A. (2023). Threats detection in the internet of things using convolutional neural networks, long short-term memory, and gated recurrent units. Mesopotamian Journal of cybersecurity, 2023, 22-29. https://doi.org/10.58496/MJCS/2023/005

Bello, A. B., Ogundipe, A. O., George, A. A., & Anifowose, O. (2025). The role of AI and machine learning in cybersecurity: Advancements in threat detection, anomaly detection and automated response. International Journal of Science and Research Archive, 14(2), 1587-1597. https://doi.org/10.30574/ijsra.2025.14.2.0542.

Besta, M., Gerstenberger, R., Peter, E., Fischer, M., Podstawski, M., Barthels, C., ... & Hoefler, T. (2023). Demystifying graph databases: Analysis and taxonomy of data organization, system designs, and graph queries. ACM Computing Surveys, 56(2), 1-40. https://doi.org/10.1145/3604932.

Biswas, S., & Dhanekula, A. (2024). Graph neural network models for predicting cyber attack patterns in Critical infrastructure systems. Review of Applied Science and Technology, 3(01), 68-105. https://doi.org/10.63125/pmnqxk63

Bonderud, D. (2024). Cost of a data breach in 2024 for the financial industry. Ibm.com. https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry

Borrohou, S., Fissoune, R., & Badir, H. (2024, November). Critical role of data transformation in preprocessing: methods, algorithms, and challenges. In International Conference on Model and Data Engineering (pp. 108-122). Cham: Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-87719-3_9

Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM computing surveys (CSUR), 41(3), 1-58. https://doi.org/10.1145/1541880.1541882

Dhoundiyal, A., Agrawal, K., Shreya, Jha, V., & Suhag, D. (2025). A Review of Hybrid Defences for IoT: Rule-Based Systems and GANs. In International Conference on Data Analytics & Management (pp. 125-137). Cham: Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-03751-0_11.

Ding, J., Qian, P., Ma, J., Wang, Z., Lu, Y., & Xie, X. (2024). Detect insider threat with associated session graph. Electronics, 13(24), 4885. https://doi.org/10.3390/electronics13244885

Eberle, W., Graves, J., & Holder, L. (2010). Insider threat detection using a graph-based approach. Journal of Applied Security Research, 6(1), 32-81. https://doi.org/10.1080/19361610.2011.529413

Ekle, O. A., & Eberle, W. (2024). Anomaly detection in dynamic graphs: A comprehensive survey. ACM Transactions on Knowledge Discovery from Data, 18(8), 1-44. https://doi.org/10.1145/3669906.

Georgiadou, A., Mouzakitis, S., & Askounis, D. (2022). Detecting insider threat via a cyber-security culture framework. Journal of Computer Information Systems, 62(4), 706-716. https://doi.org/10.1080/08874417.2021.1903367.

Ghosh, U., Paul, A., Sarkar, D., Dey, M., & Paul, P. (2024, November). Graph-based approaches in cybersecurity: A comprehensive survey. In International Conference on Smart Systems and Wireless Communication (pp. 465-477). Singapore: Springer Nature Singapore. https://doi.org/10.1007/978-981-96-1348-9_35.

Greitzer, F. L., & Hohimer, R. E. (2011). Modeling human behavior to anticipate insider attacks. Journal of Strategic Security, 4(2), 25-48. http://dx.doi.org/10.5038/1944-0472.4.2.2

Hamilton, W., Ying, Z., & Leskovec, J. (2017). Inductive representation learning on large graphs. Advances in neural information processing systems, 30.

Hasan, M. K. (2024). New heuristics method for malicious urls detection using machine learning. Wasit Journal of Computer and Mathematics Science, 3(3), 60-67. https://doi.org/10.31185/wjcms.267.

Hasan, M. M., & Nijhum, A. M. (2024). Deep learning and graph neural networks for real-time cybersecurity threat detection. Review of Applied Science and Technology, 3(01), 106-142. https://doi.org/10.63125/dp38xp64

Ji, R., Padha, D., Singh, Y., & Sharma, S. (2024). Review of intrusion detection system in cyber physical system based networks: characteristics, industrial protocols, attacks, data sets and challenges. Transactions on Emerging Telecommunications Technologies, 35(9), e5029. https://doi.org/10.1002/ett.5029.

Jin, M., Koh, H. Y., Wen, Q., Zambon, D., Alippi, C., Webb, G. I., ... & Pan, S. (2024). A survey on graph neural networks for time series: Forecasting, classification, imputation, and anomaly detection. IEEE transactions on pattern analysis and machine intelligence, 46(12), 10466-10485. https://doi.org/10.1109/TPAMI.2024.3443141

Kesarwani, V., & Rajesh, E. (2024, December). Advanced detection of malicious urls using machine learning: a comparative analysis of svm, random forest, and logistic regression. In 2024 1st International Conference on Advances in Computing, Communication and Networking (ICAC2N) (pp. 228-233). IEEE. https://doi.org/10.1109/ICAC2N63387.2024.10895286.

Khemani, B., Patil, S., Kotecha, K., & Tanwar, S. (2024). A review of graph neural networks: concepts, architectures, techniques, challenges, datasets, applications, and future directions. Journal of Big Data, 11(1), 18. https://doi.org/10.1186/s40537-023-00876-4.

Lagraa, S., Husák, M., Seba, H., Vuppala, S., State, R., & Ouedraogo, M. (2024). A review on graph-based approaches for network security monitoring and botnet detection. International Journal of Information Security, 23(1), 119-140. https://doi.org/10.1007/s10207-023-00742-7

Li, L., Qiang, F., & Ma, L. (2024, April). Advancing cybersecurity: graph neural networks in threat intelligence knowledge graphs. In Proceedings of the International Conference on Algorithms, Software Engineering, and Network Security (pp. 737-741). https://doi.org/10.1145/3677182.3677314.

Lian, J., Ren, W., Li, L., Zhou, Y., & Zhou, B. (2023). Ptp-stgcn: pedestrian trajectory prediction based on a spatio-temporal graph convolutional neural network. Applied Intelligence, 53(3), 2862-2878. https://doi.org/10.1007/s10489-022-03524-1

Liang, H., Zhang, Z., Hu, C., Gong, Y., & Cheng, D. (2023). A survey on spatio-temporal big data analytics ecosystem: resource management, processing platform, and applications. IEEE Transactions on Big Data, 10(2), 174-193. https://doi.org/10.1109/TBDATA.2023.3342619.

Liu, K., Wang, F., Ding, Z., Liang, S., Yu, Z., & Zhou, Y. (2022). Recent progress of using knowledge graph for cybersecurity. Electronics, 11(15), 2287. https://doi.org/10.3390/electronics11152287.

Mink, J., Benkraouda, H., Yang, L., Ciptadi, A., Ahmadzadeh, A., Votipka, D., & Wang, G. (2023). Everybody’s got ML, tell me what else you have: Practitioners’ perception of ML-based security tools and explanations. In 2023 IEEE Symposium on Security and Privacy (SP) (pp. 2068-2085). IEEE. https://doi.org/10.1109/SP46215.2023.10179321.

Mohanty, R. K. (2025). Deep learning for analyzing user and entity behaviors: techniques and applications. In Hybrid Soft Computing Techniques for Machine Learning and Optimization (pp. 121-148). IGI Global Scientific Publishing. http://doi.org/10.4018/979-8-3693-6864-0.ch006

Padmavathi, B., & Muthukumar, B. (2023). A deep recursively learning LSTM model to improve cyber security botnet attack intrusion detection. International Journal of Modeling, Simulation, and Scientific Computing, 14(02), 2341018. https://doi.org/10.1142/S1793962323410180.

Partovian, S., Bucaioni, A., Flammini, F., & Thornadtsson, J. (2023). Analysis of log files to enable smart-troubleshooting in industry 4.0: a systematic mapping study. IEEE Access, 12, 147640-147658. https://doi.org/10.1109/ACCESS.2023.3342365.

Pazho, A. D., Noghre, G. A., Purkayastha, A. A., Vempati, J., Martin, O., & Tabkhi, H. (2023). A survey of graph-based deep learning for anomaly detection in distributed systems. IEEE Transactions on Knowledge and Data Engineering, 36(1), 1-20. https://doi.org/10.1109/TKDE.2023.3282898.

Prabhu, S., & Thompson, N. (2022). A primer on insider threats in cybersecurity. Information Security Journal: A Global Perspective, 31(5), 602-611. https://doi.org/10.1080/19393555.2021.1971802.

Qiu, Y., Sun, L., Wu, J., Gao, Y., & Yang, J. (2024). Rule-Based Learning for Explainable XGBoost Internal Threat Detection. In International Conference on Data and Information in Online (pp. 476-490). Cham: Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-97352-9_28.

Sankaewtong, K., Kim, T., Tessone, C. J., & Ikeda, Y. (2025). SoK: Advances in Anomaly Detection Techniques for Cryptoasset Transactions. IEEE Access, 13, 202576-202618. https://doi.org/10.1109/ACCESS.2025.3636560.

Saxena, N., Hayes, E., Bertino, E., Ojo, P., Choo, K. K. R., & Burnap, P. (2020). Impact and key challenges of insider threats on organizations and critical businesses. Electronics, 9(9), 1460. https://doi.org/10.3390/electronics9091460.

Shakil, N. A. F., Mia, R., & Ahmed, I. (2023). Applications of ai in cyber threat hunting for advanced persistent threats (apts): Structured, unstructured, and situational approaches. Journal of Applied Big Data Analytics, Decision-Making, and Predictive Modelling Systems, 7(12), 19-36. https://polarpublications.com/index.php/JABADP/article/view/2023-12-07

Sharma, P., Homkar, A., Jha, S., Somasekar, J., Wbaid, S., & Dixit, K. K. (2025). Efficient Cybersecurity Threat Analysis Through Anomaly Detection and Graph Summarization. In Graph Mining: Practical Uses and Instruments for Exploring Complex Networks (pp. 43-53). Cham: Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-93802-3_4.

Skopik, F., Wurzenberger, M., Höld, G., Landauer, M., & Kuhn, W. (2022). Behavior-based anomaly detection in log data of physical access control systems. IEEE Transactions on Dependable and Secure Computing, 20(4), 3158-3175. https://doi.org/10.1109/TDSC.2022.3197265.

Subrahmanyam, S. (2025). Behavioral analysis for threat detection. In Handbook of AI-Driven Threat Detection and Prevention (pp. 95-115). CRC Press.

Thiyagarajan, G. P., Shree, K. R., & Kumar, P. P. (2026). Rule-Based Data Mining for Detecting Cyber Threats in Digital Healthcare Environments: A Review. AI Techniques for Association Rule Mining in Medical Data: Trends and Practical Applications, 365-392. http://doi.org/10.4018/979-8-3373-6691-3.ch013.

Verma, K. K., Singh, B. M., & Dixit, A. (2022). A review of supervised and unsupervised machine learning techniques for suspicious behavior recognition in intelligent surveillance system. International Journal of Information Technology, 14(1), 397-410. https://doi.org/10.1007/s41870-019-00364-0.

Wang, Y., Jodoin, P. M., Porikli, F., Konrad, J., Benezeth, Y., & Ishwar, P. (2014). CDnet 2014: An expanded change detection benchmark dataset. In Proceedings of the IEEE conference on computer vision and pattern recognition workshops (pp. 387-394).

Ying, R., He, R., Chen, K., Eksombatchai, P., Hamilton, W. L., & Leskovec, J. (2018, July). Graph convolutional neural networks for web-scale recommender systems. In Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining (pp. 974-983). https://doi.org/10.1145/3219819.3219890

Zamanzadeh Darban, Z., Webb, G. I., Pan, S., Aggarwal, C., & Salehi, M. (2024). Deep learning for time series anomaly detection: A survey. ACM Computing Surveys, 57(1), 1-42. https://doi.org/10.1145/3691338

Zheng, C., Hu, W., Li, T., Liu, X., Zhang, J., & Wang, L. (2022, May). An insider threat detection method based on heterogeneous graph embedding. In 2022 IEEE 8th Intl Conference on Big Data Security on Cloud (BigDataSecurity), IEEE Intl Conference on High Performance and Smart Computing,(HPSC) and IEEE Intl Conference on Intelligent Data and Security (IDS) (pp. 11-16). IEEE. https://doi.org/10.1109/BigDataSecurityHPSCIDS54978.2022.00013

Downloads

Published

2026-09-01

How to Cite

Irshad, M. ., Shafiq, M. F. ., & Sajjad, M. N. . (2026). Insider Threat Prediction Using Graph Analysis. American Journal of Data Science and Artificial Intelligence, 2(2), 5-19. https://doi.org/10.54536/ajdsai.v2i2.8088

Similar Articles

1-10 of 13

You may also start an advanced similarity search for this article.